Skip to content

Commit 8d4f58c

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@bf35695
1 parent c1abd53 commit 8d4f58c

2 files changed

Lines changed: 3 additions & 3 deletions

File tree

advisories/_posts/2026-05-18-CVE-2026-33637.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ advisory:
99
gem: faraday
1010
cve: 2026-33637
1111
ghsa: 5rv5-xj5j-3484
12-
url: https://github.com/lostisland/faraday/security/advisories/GHSA-5rv5-xj5j-3484
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-33637
1313
title: Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2 - protocol-relative
1414
URI objects still bypass host scoping
1515
date: 2026-05-18
@@ -38,7 +38,7 @@ advisory:
3838
that believe they are constrained to a fixed base URL. If the
3939
connection carries default headers or query parameters, those
4040
values are forwarded to the attacker-selected host.
41-
cvss_v3: 0.0
41+
cvss_v3: 6.5
4242
unaffected_versions:
4343
- "< 2.0.0"
4444
patched_versions:
@@ -50,5 +50,4 @@ advisory:
5050
- https://github.com/lostisland/faraday/security/advisories/GHSA-5rv5-xj5j-3484
5151
- https://github.com/advisories/GHSA-33mh-2634-fwr2
5252
- https://github.com/advisories/GHSA-5rv5-xj5j-3484
53-
notes: "- ZERO CVSS value in GHSA and NVD\n"
5453
---

advisories/_posts/2026-05-18-CVE-2026-45363.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,7 @@ advisory:
5858
- ">= 3.2.0"
5959
related:
6060
url:
61+
- https://www.cve.org/CVERecord?id=CVE-2026-45363
6162
- https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x
6263
- https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f
6364
- https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0

0 commit comments

Comments
 (0)